Cybersecurity
Cisco patches Nexus and IOS XR flaws
Cisco issued fixes for a Nexus 9000 switching flaw that could let a reachable attacker run code as root, and for an IOS XR hardening release covering seven grouped CVEs.
- Cisco patched a flaw affecting 10 Silicon One-based Nexus 9000 switch models.
- Cisco said the issue could let a reachable attacker run code as root or crash and reload the device, and it assigned CVE-2026-20212 a CVSS score of 9.8.
- Cisco said it had not seen malicious use by 2 September and advised customers to use Software Checker, an iACL or Live Protect shield lp00031 as temporary measures.
- Cisco said 111 IOS XR releases were affected, with 14 already covered by SMUs, four waiting for SMUs and 93 needing an upgrade first.
- On the same day, Cisco fixed S/MIME flaws in Secure Email and a denial-of-service bug in several phone lines, while Sygnia separately reported Fire Ant activity on IOS XR routers.
Cisco patched a flaw in 10 Silicon One-based Nexus 9000 switch models. The advisory said a service exposed on TCP ports 43210 and 43211 in the default Layer 3 VRF could accept crafted input and execute it with root privileges, and that a failed attempt could crash S1HAL and reload the device.
Cisco said on 2 September that it had not seen abuse of the issue. It told customers to use Software Checker, an infrastructure ACL that blocked the two ports, or the temporary Live Protect shield lp00031 while fixed releases were confirmed.
Cisco also published an IOS XR hardening release that grouped seven CVEs by weakness class. It said two scored 9.8 and five scored between 8.2 and 8.8, and that 111 IOS XR releases were affected, with 14 already covered by SMUs, four waiting for SMUs and 93 needing an upgrade first.
The XR7 (LNT) platforms named in the advisory included Cisco 8000 Series, NCS 1010, NCS 540L and NCS 5700 Series. Cisco also fixed S/MIME decryption flaws in Secure Email and a denial-of-service bug in Desk Phone 9800, IP Phone 7800, IP Phone 8800 and Video Phone 8875 devices registered to Unified Communications Manager.
Separately, Sygnia said Fire Ant had used IOS XR router implants that hid syslog output, filtered show-command results and supported a concealed GRE tunnel. It said it had not identified the first access path.
Named in this story
People
- Russ Smoak
- was Cisco's vice president of information security
Companies
- Cisco
- released the patches and advisories
- Sygnia
- reported the Fire Ant investigation
Organisations
- Fire Ant
- was the China-nexus threat actor Sygnia described
Products and systems
- Nexus 9000
- was the switch family affected by CVE-2026-20212
- NX-OS
- was the switch operating system whose releases were listed as affected
- IOS XR
- was the router operating system covered by the hardening release
- Secure Email
- was the mail product with S/MIME flaws fixed the same day
- Desk Phone 9800
- was a phone line with a denial-of-service flaw fixed
- IP Phone 7800
- was a phone line with a denial-of-service flaw fixed
- IP Phone 8800
- was a phone line with a denial-of-service flaw fixed
- Video Phone 8875
- was a phone line with a denial-of-service flaw fixed
- Unified Communications Manager
- was the system those phones were registered to
- Cisco 8000 Series
- was among the XR7 platforms with a dedicated SMU
- NCS 1010
- was among the XR7 platforms named in the SMU notes
- NCS 540L
- was among the XR7 platforms named in the SMU notes
- NCS 5700 Series
- was among the XR7 platforms named in the SMU notes
- Live Protect shield lp00031
- was the temporary mitigation Cisco offered for the Nexus issue
How the source tells it
A largely technical advisory, but it repeatedly uses criticality, root-level impact and time-sensitive mitigation language to create alarm, while tempering it with no-abuse and stopgap notes.
- alarm critical severity and root-level code execution framing
- urgency repeated upgrade, mitigation and no-workaround guidance
- reassurance explicit no-abuse note and temporary defences